CVE-2024-8687: PAN-OS: Cleartext Exposure of GlobalProtect Portal Passcodes
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally permit them to do so.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8687?
CVE-2024-8687 is classified as an information exposure vulnerability in Palo Alto Networks PAN-OS.
How do I fix CVE-2024-8687?
To fix CVE-2024-8687, upgrade to the latest version of Palo Alto Networks PAN-OS or GlobalProtect that addresses this vulnerability.
What are the affected versions for CVE-2024-8687?
CVE-2024-8687 affects multiple versions of Palo Alto Networks PAN-OS and GlobalProtect from version 8.1.0 up to specific higher versions.
What type of vulnerability is CVE-2024-8687?
CVE-2024-8687 is an information exposure vulnerability that allows end users to discover sensitive configuration data.
Is CVE-2024-8687 a remote vulnerability?
CVE-2024-8687 can be exploited by a local user with access to the GlobalProtect client.